PT-2021-4099 · Unknown+1 · Cyrus Imap+1
Published
2021-05-05
·
Updated
2025-05-06
·
CVE-2021-32056
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Cyrus IMAP versions 3.2.7 and earlier, 3.3.x, and 3.4.x before 3.4.1
Description
The issue allows remote authenticated users to bypass intended access restrictions on server annotations, which can cause replication to stall. This is related to incorrect permission assignment for a critical resource. Exploitation of the issue may allow a remote attacker to cause a denial of service.
Recommendations
For Cyrus IMAP versions 3.2.7 and earlier, update to version 3.2.7 or later.
For Cyrus IMAP version 3.3.x, update to version 3.4.1 or later.
For Cyrus IMAP version 3.4.x before 3.4.1, update to version 3.4.1 or later.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Cyrus Imap